Re: Advice on setting up a shell server
Stefan 'Kaishakunin' Schumacher <[email protected]>
| Newsgroups | gmane.os.netbsd.help |
|---|---|
| Message-ID | <[email protected]> |
Also sprach Martijn van Buul ([email protected]) > * Stefan 'Kaishakunin' Schumacher: > > Use Systrace to systrace the login shell and restrict any access to > > evil[tm] binaries, such as ftp/telnet. > > pray tell, what's evil[tm] about ftp/telnet? Are you going to restrict > browsers or things like wget/fetch too? > > I'm not talking about ftpd or telnetd, but I *REALLY* don't see what's the > evilness of someone acessing a ftp site somewhere, or accessing one of the > few remaining telnet services It depends on your local security policy what is declared evil and what not. Things you might find OK are forbidden on other sites. So what? > > You can also use systrace to forbid the use of binaries in the home dirs of > > students or to restrict=20 eg. SSH to your private network. > > Why don't you also change the shell to /bin/nologin and pull the network plug? > :) > > Security is one thing. Turning the whole project pointless, all for the > benefit of security is another. At least, I'm sure that the intention of > this project is to give students a usuable account, and not to give them > something they cannot sensibly use or access. First "usuable account" has to be defined, than one can create a security policy for it. Or discuss single arrangements. Like I said above, security is site-dependent and what I gave as _example_ is useful on my servers. YMMV. -- Pedites pugnas decernent http://www.jaegerseiten.de Horrido! http://www.net-tex.de http://www.cryptomancer.de
signature.asc
(application/pgp-signature, 186 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (NetBSD) iD8DBQFFxJQPEfTEHrP7rjMRAmMHAJ9Rv8PxmJSnJFtw3WDCSXkILI4F2QCgq2eO qa5W8mcURr/i06RhfJ2oij4= =gnle -----END PGP SIGNATURE-----